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(54) Illegal view and copy protection method in digital video system and controlling method 
thereof 



(57) Illegal view and copy protection method in a dig- 
ital video system for preventing an illegal user from view- 
ing the digital video system and copying therefrom, by 
setting a descrambting method which decrypts split key- 
streams adopting a smart card, including a determina- 
tion step for determining received data of having been 
scrambled: a reproduction step, if the received data was 
determined to be scrambled data in the determination 
step, splitting the scrambled data into a bitstream and a 
keystream for decrypting the split keystream for reading 
in key information, and descrambting the split bitstream 
according to the read in key information for displaying the 
bitstream on a display: a recording step for, if the 
received data was determined to be scrambled data in 
the determination step, recording the scrambled data on 
a recording medium either as scrambled data of a bit- 
stream and a keystream according to a recording or cop- 
ying mode, or after splitting the scrambled data into a 
bitstream and a keystream. encrypting the split key- 
stream, and mixing the encrypted keystream with the bit- 
stream: and a transporting step, if the received data was 
determined to be scrambled data in the determination 
step, splitting the scrambled data into a bitstream and a 
keystream for transporting the split keystream either 
after decrypting the split keystream with respect to key 
information from recording side according to a PPC 
mode or a back-up copy mode, or after decrypting the 
split keystream two times with respect to key information 
of its own and key information from recording side; 
thereby the reproduction step, the recording step and the 
transporting step can be performed simultaneously or 
selectively. 
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Description 

Background of the Invention 

s The present invention relates to an illegal view and copy protection technique for a digital video system, and more 

particularly, to an illegal view and copy protection method in a digital video system for preventing an illegal user from 
viewing the digital video system and copying therefrom, by setting a descrambling method which decrypts split key- 
streams adopting a smart card. 

In a general digital video system, there has been a keen interest in implementing a conditional access (CA) system 
io for an illegal viewing protection. 

In such a CA system, a broadcasting signal is scrambled at charged channels such as in a cable television or a 
satellite broadcasting service to be broadcasted. Therefore, only a user who paid normally can view a program properly 
through descrambling. 

For example, a satellite broadcasting receiver or a Grand Alliance (GA) system, which is a standard of an advanced 
is television ( ATV) in U.S.A. has a function for supporting a CA. Also, scrambling/descrambling apparatus, such as a video 
cipher manufactured by Gl, which can be used for a satellite broadcasting, have been commonly used. 

Video cipher manufactured by Gl is generally used for the scrambling system for a CA system, which is based in 
U.S. Patent No. 4,61 3,901 by Gilhousen, disclosing a system and method, in which a TV signal transported via a normal 
user's descrambler is scrambled in a charged TV system to be broadcasted and then is selectively descrambled in the 
20 user s descrambler. A video cipher system for performing a descrambling is implemented by adopting a smart card, 
which is disclosed in U.S. Patent No. 5.1 1 1 .504. This is implemented such that the system proposed by Gilhousen is 
partitioned into two parts, that is. an information processor corresponding to a descrambler and a security element which 
can be replaced by a smart card. 

Therefore, by adopting the above method, the scrambling system is implemented as shown in FIG. 1 , and the 
25 descrambling system is implemented as shown in FIG. 2. 

In other words, a conventional illegal viewing protecting apparatus for a digital video system includes a scrambler 
101 for scrambling a TV signal in accordance with a common category key (CK) and an initialization vector (PK) and 
outputting the scrambled TV signal (SV Q ) and scrambling information E U(0 )E U(S )(CK) and Ec K (PK). a smart card 103 
for encrypting information for descrambling, A(D) and A(S), with respect to descrambling information U(S). and an infor- 
30 mation processor 102 for decrypting the information for descrambling, E A <o)[E A (S)(WK)], to descramble the TV signal 
(SV 0 ) transported from scrambler 101 and restoring the same into original TV signal 0V o . 

Here, A(D) is an authentication key of information processor 102, A(S) is an authentication key of smart key 103. 
U(D) is a unit key of information processor 102. and U(S) is a unit key of smart key 103. 

At this time, scrambler 101 includes a first encrypter 1 1 1 for encrypting a common category key (CK) with respect 
35 to descrambling information U(D) and U(S). a second encrypter 112 for encrypting an initialization vector (PK) with 
respect to the common category key (CK), a third encrypter 1 13 for encrypting the initialization vector (PK) with respect 
to the output Eck(PK) of second encrypter 112. and a scrambling executing party 1 14 for scrambling a TV signal Vj in 
accordance with the output WK of third encrypter 113. 

The operation of the conventional apparatus having the aforementioned configuration will now be described. 
40 First in the case of transporting a TV signal in a transport system, scrambler 101 operates such that the common 
category key (CK) is encrypted with respect to the descrambling information U(0) and U(S) by first encrypter 1 1 1 . the 
initialization vector (PK) is encrypted with respect to the common category key (CK) by second encrypter 1 12, the 
initialization vector (PK) is encrypted with respect to the output E CK (PK) of second encrypter 1 1 2 by third encrypter 1 13. 
to then be output to scrambling executing party 114. 
45 At this time, scrambling executing party 1 1 4 scrambles the TV signal Vj in accordance with the output WK of third 
encrypter 113. Here, the scrambling information WK is expressed in E ECK (pk)(PK). 

Accordingly, scrambler 101 transports information E U(D) E U(S) (CK) encrypted with respect to the common category 
key (CK). the information EckCP*) encrypted initialization vector (PK) and the scrambled TV signal SVo, to information 

processor 102. . , 

so In case of descrambling the scrambled TV signal SV ot smart card 103 encrypts the information WK necessary for 
descrambling with respect to authentication information A(D) of information processor 102 and its own authentication 
information A(S). and then generates the encrypted descrambling information E A(D) [E A(S )(WK)] to information processor 

102. 

Accordingly, information processor 102 decrypts the encrypted descrambling information E A(D) [E A(S) (WK)] gener- 
55 ated from smart card 103 and descrambles the TV signal SV Q transported from scrambler 101 using the encrypted 
descrambling information E A(D) [E A(S )(WK)l, thereby restoring the same into the original TV signal DV 0 . 

Here, the encryption in transporting the information between information processor 102 and smart card 103 is 
adopted for enhance the security from the illegal view and copy. 
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For example, the specification of a GA-HDTV system supports the CA system and includes various functions nec- 
essary for transport protocols. 

These functions are flexible and useful in that they support all possible descrambling methods and key encryption 
methods, and bitstreams are selectively scrambled so that a C A function can be adopted in the unit of an element stream. 
5 Here, the scrambling randomizes data bitstream according to information data, and the encryption converts infor- 

mation data in order to protect the information data from illegal users. 

In other words, the CA system makes the transported data random and disables the illegal users' decoders to be 
decoded improperly by means of a scrambler but allows the legal users' decoders to decode the received TV broadcasting 
signals properly by supplying information for initializing a descrambler circuit 
io The CA transport MPEG protocol for such operation is implemented by the format shown in FIG. 3 and supports 
the CA function as follows. 

First, a transport-scrambling-control field of 2 bits notifies whether or not a transport stream is scrambled and which 
scrambling key is used. 

Second, each data is inserted into the GA transport system using a transport-private-data field positioned within 
is adaptation header of the transported stream, and encrypted scrambling information is stored in the field. 

The CA transport MPEG protocol transports a transport header, a packetized elementary stream (PES) and audio 
and video data independently or concurrently. The transport protocol includes a header link header region, an adaptation 
header region and a payload region. 

Here, the link header has a length of 4 bytes and the adaptation head has a variable length. 
20 The transport-scrambling-control field is inserted into the link header. A field value of "00" is recognized as being 
not scrambled. "10" is recognized as being an even key. "1 1 " is recognized as being an odd key. and "01" is recognized 
as being reserved. 

The adaptation header includes a flag bit and transport-private-data field, and the flag bit includes transport-private- 
data flag of one bit. The PES header of the CA transport M PEG protocol shown in FIG. 3 is constructed as shown in FIG. 4. 
25 A field for a digital storage media (DSM) such as a digital video cassette recorder (OVCR) exists in the PES header. 
Such a field include a PES header flag region having a length of 1 4 bits and a PES header field having a variable length. 
The PES header flag region includes a 1 -bit copyright (CR) flag, a 1 -bit original-or<opy flag, a 2-bit PD flag, a 1 -bit TM 
flag and a 1 -bit AC flag. 

The PES header field has a variable length and its region is partially set by the PD. TM and AC flags contained in 
30 the PES header flag region. 

In other words. PTS/DTS regions do not exist in the PES header field if the PD flag value is "00," PTS/DTS of 40 
bits exist if the PD flag value is "10," PTS/DTS of 80 bits exist if the PD flag value is "11." A DSM trick mode does not 
exist if the TM flag value is "0." and the DSM trick mode becomes 8 bits if the TM flag value is "1 ." Also, if the AC flag 
is set to "1 ." an additional copy information field becomes 8 bits. 
35 The scrambling information is transported by adopting the above-described format and the descrambling process 
using the information is shown in FIG. 5. 

Here, since the descrambling system decrypts the next encrypted key together with the key being used for the 
current descrambling, the descrambler stores at least two keys, that is, an odd key and an even key. 

Also, the scrambling system sets a value of the transport-scramWing-control field within the link header according 
40 to the descrambling method of the current transport stream to then transport the same. 

Accordingly, the descrambler determines an even key or an odd key according to the value of the transport-scram- 
bling-corrtrol field of the decrypted transport head from the received data and then descrambles the received data to 
then be decrypted. 

In other words, when the data having the format shown in FIG. 5 is transported and descrambler descrambles the 
45 K 2n . , -th frame with the odd key according to the value of the transport-scrambling-control field decrypted in smart card, 
smart card decrypts the transport-scrambling-control field of K 2n -th frame to be descrambed next. These operations are 
sequentially performed. 

An ATV decoder for performing the CA function may be implemented as shown in FIG. 6. The ATV decoder 110 
incorporates a descrambler necessitating a fast operation into a transport demultiplexer 1 05 and performs the descram- 
so bling by a DES algorithm or a stream cipher algorithm using a PN sequence. The key encrypted by ATV decoder 1 1 0 
is decrytped in smart card 103. Here, the interface between smart card 103 and ATV decoder 1 10 is executed in accord- 
ance with the ISO-7816 standard specification. 

In other words, in the embodiment shown in FIG. 6, a signal received from a tuner is demodulated in a demodulator 
& error corrector 104 and then the errors generated during transport are corrected by an RS decoding and are input to 
55 transport demultiplexer 1 05 of ATV decoder 1 1 0 to then be descrambled. 

At this time, a microcontroller 109 operates descrambled control and data and transports the encryption information 
for descrambling to smart card 103. Smart card 103 decrypts the transported encryption information to transport the 
same to ATV decoder 1 10. 
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At this time, transport demultiplexer 105 restores a compressed video and audio signals, control signal and data 
according to the descrambling information. 

Accordingly, a video decoder 107 extends the compressed video signal and temporarily stores the extended signal 
in a memory 106 and then outputs the stored data to display a video. An audio decoder 108 extends the compressed 
5 audio signal and then reproduce an audio. 

Also, microcontroller 1 09 reads the control signal and data output from transport demultiplexer 1 05 and controls the 
operations of video decoder 107 and audio decoder 108. 

Among various methods used for encryption, a block-cipher algorithm such as DES and a stream-cipher algorithm 
using the PN sequence are most widely used. 
10 However, since these methods perform encryption and decryption only with a encrypted signal, a key management 
and a key distribution are hard to accomplish. 

Therefore, in order to solve the above problem, a public key encryption method has been proposed in U.S. Patent 
No. 4,200,770. This method performs encryption using a public key and performs decryption using his own secret key. 

The public key encryption method has been improved and implemented as an encryption system, which is known 
is as an RSA encryption algorithm disclosed in U.S. Patent No. 4,405,829. However, this public key encryption method is 
not suitable for fast encryption. 

The CA system aims to protect an illegal viewing. However, programs distributed through a DSM such as a DVCR 
cannot be protected from the illegal copying. 

In other words, the protection of the program distributed by a recording medium such as DSM means the illegal 
20 copying protection. However, the copy protection method adopted in a conventional analog VCR system is difficult to 
be adopted in a digital storage media. Also, research into the copy protection method for D SM has not yet been developed 
well. 

Summary of the Invention 

25 

Preferred and particular embodiments of the present invention seek to address the problems of the prior art and 
provide illegal view and copy protection method in a digital video system and a controlling method thereof for protecting 
illegal view and copy, in which encrypted key is decrypted in a smart card by transporting a scrambled bitstream and 
the encrypted key used for scrambling to different pathsrand the bitstream is descrambled in accordance with the infor- 
30 mation. and normal decoding is not performed only by the bitstream. 

Further embodiments of the present invention adopt a smart card in the C A system so that the charge is automatically 
checked to enforce the pay per view (PPV) function and to upgrade the performance of the system by adding various 
functions by way of replacement of the smart card. 

Still other embodiments of the present invention reduce the key quantity of the data to be protected greatly by splitting 
35 the transported data and to make the system inoperative with an illegal smart card by automatic performance of authen- 
tication and key exchange during power-on or connection to a digital recording /reproduction device for recording, thereby 
increasing the reliability of the protection function. 

According to one aspect of the present invention, there is provided an illegal view and copy protection method in a 
digital video system, including:* a determination step for determining received data of having been scrambled; a repro- 
40 duction step, if the received data was determined to be scrambled data in the determination step, splitting the scrambled 
data into a bitstream and a keystream for decrypting the split keystream for reading in key information, and descrambling 
the split bitstream according to the read in key information for displaying the bitstream on a display; a recording step for. 
if the received data was determined to be scrambled data in the determination step, recording the scrambled data on a 
recording medium either as scrambled data of a bitstream and a keystream according to a recording or copying mode. 
45 or after splitting the scrambled data into a bitstream and a keystream. encrypting the split keystream. and mixing the 
encrypted keystream with the bitstream; and a transporting step, if the received data was determined to be scrambled 
data in the determination step, splitting the scrambled data into a bitstream and a keystream for transporting the split 
keystream either after decrypting the split keystream with respect to key information from recording side according to a 
PPC mode or a back-up copy mode, or after decrypting the split keystream two times with respect to key information of 
so its own and key information from recording side, thereby the reproduction step, the recording step and the transporting 
step can be performed simultaneously or selectively. 

According to other aspect of the present invention, there is provided an illegal view and copy protection method in 
a digital video system, including: a reproduction step, on reception of scrambled data, splitting the scrambled data into 
a bitstream and a keystream for decrypting the split keystream for reading in key information, and descrambling the split 
55 bitstream according to the read in key information for displaying the bitstream on a display; and a recording step for. on 
reception of scrambled data, recording the scrambled data on a recording medium as scrambled data of a bitstream 
and a keystream; thereby the reproduction step and the recording step can be performed simultaneously or selective^ 
According to another aspect of the present invention, there is provided an illegal view and copy protection method 
in a digital video system, including: a determining step for determining the mode of the keystream being a back-up copy 
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mode or a PPC mode: a first transportation step for. if the mode was determined to be a PPC mode in the determining 
step decrypting the keystream with respect to key information from a recording side for transporting the keystream; a 
first recording step for encrypting the keystream transported in the first transportation step with respect to the key infor- 
mation from the recording side and inserting the encrypted keystream into a position corresponding to an index code, 
for recording the keystream together with a bitstream on a recording medium; a second transportation step for. if the 
mode was determined to be a back-up copy mode in the determining step, decrypting the keystream for two times with 
respect to its own key information and the key information from the recording side for transporting the keystream; and 
a second recording step for encrypting the keystream transported in the second transportation step with respect to the 
key information from the recording side and inserting the encrypted keystream into the position corresponding to the 
index code, tor recording the keystream together with the bitstream on a recording medium. 

According to further aspect of the present invention, there is provided an illegal view and copy protection method 
in a digital video system, including: a PPC' mode reproduction step for. having determined the recording medium being 
a PPC recording medium on detection of a keystream at reproduction from a recording medium, encrypting the key- 
stream with respect to its own key information and decrypting the keystream with respect to its own key information tor 
reading in the key information, for descramblihg the bitstream using both the read in key information and an .ndex code; 
and a back-up copy mode reproduction step for. having determined the recording medium being a back-up copy record- 
ing medium on detection of a keystream decrypted with respect to its own key °^^^' n ? 
medium, encrypting the keystream for two times with respect to its own key information and the key ^ r ™*^°^ a 
recording side and decrypting the keystream with respect to its own key information for reading in the key .nformat.on. 
20 for descramttinq the bitstream using both the read in key information and an index code. 

in a digital Jeo system, including: demodulating * error correcting means tor ^^^u^ng^^atog 
broadcasting signal and Preceding said signal: copy protection processing means ^anspcrtngthe outputofsaa 
debating * error correcting means * a digital recording/rep^^ 

reproduced from said digital recording/reproduction device into a bitstream and a keystream. and encrypting the split 
k^sVe^ dicing means tor descrambling the bitstream from said demodulating & error correcting means or the 
^pSo^ess,^means according S ^ 

keXamSfsaklcopy protection processing means tor applying to said decoding means as d^rantxirxj^rr^ 

" Snr^Sother aspectof the presem Mention, there is provded an illegal view a 
in a diaital video system including: first copy protection processing means for splitting reproduction data from a first 
^S£S^hS!S^JL intoTbLream and a keystream and encrypting the split keystream. first and 

of the smart cart, an aloo-ilhm storaa. n»mory to. storing an ""^att^ «* • ,xocetS " ** ° MeU "' S 

45 smart card. 

p f j ft f pftgrription of |Ha Drawings 
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The above objects and advantages of the present invention will become more apparent by describing in detail a 
preferred embodiment thereof with reference to the attached drawings in which. 



FIG. 2 
FIG. 3 
55 FIG. 4 
FIG. 5 
FIG. 6 
FIG. 7 
FIG. 8 



FIG. 1 is a block diagram of a general scrambler ; 
is a block diagram of a general descrambler; 
illustrates a transport format; 
illustrates a PES header shown in FIG. 3 m detail; 
illustrates the transport format by key distribution; 

is a detailed block diagram of the copy protection apparatus shown «n FIG. 7. 
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FIG. 9 is a detailed block diagram of the smart card shown in FIG. 7; 
FIG. 10 illustrates the splitting of the bitstream shown in FIG. 8; 
FIG. 1 1 illustrates the format of the respective bitstreams; 

FIGS. 12 through 18 illustrate the connections state of a preferred embodiment of the present invention; 
FIGS. 1 9 and 20 show the flow of signals for operation of a preferred embodiment of the present invention; and 
FIG. 21 shows the flow of signals for key exchange and authentication according to a preferred embodiment of the 
present invention' 

Detailed Description of the Invention 



The present invention is applicable to ail recording /reproduction devices that can record and reproduce a digital 
signal, and for the sake of convenience of explanation, descriptions shown hereinafter is for an embodiment in a case 
of DVCR, as an example. 

Accordingly, as shown in FIG. 7, the illegal view and copy protection apparatus in a digital video system according 
is to an embodiment of the present invention, includes a demodulator & error corrector 1 for modulating /demodulating an 
analog broadcasting signal and RS-decoding the signal, an ATV decoder 2 for descrambting the output of demodulator 
& error corrector 1 according to descrambling information, a copy protection processor 4 for splitting the scrambled 
recording signal into a bitstream and a keystream and encrypting the split keystream, and a smart card 3 for decrypting 
the split and encrypted keystream of copy protection processor 4 and the index code of ATV decoder 2 and outputting 
20 descrambling information KS to ATV decoder 2. 

Copy protection processor 4, as shown in FIG. 8. includes a RAM 1 7 for storing intrinsic key information of the smart 
card, an algorithm storage memory 1 8 for storing an encryption algorithm, and a processor 1 9 for executing an encryption 
program of algorithm storage memory 18 with the key information of RAM 1 7. 

Smart card 3 f as shown in FIG. 9. includes a first algorithm storage memory 12 for storing a decryption algorithm 
25 program for a bitstream. a second algorithm storage memory 13 for storing a decryption algorithm program of its own 
key information, a ROM 1 4 for storing its own key information, a RAM 1 5 for temporarily storing key information of another 
smart card, and a processor 1 1 for executing encryption or decryption with the storage algorithm of first and second 
algorithm storage memories 12 and 13 with respect to the key information stored in ROM 14 or RAM 15. 

At this time, processors 1 1 and 16 may be constructed by wired logic or may adopt a microprocessor. In case of 
30 adopting the microprocessor, the encryption algorithm for a smart card may be incorporated in a program. 
The operation and effect of the embodiment constructed as stated above will now be described. 
In the described embodiment, a GA bitstream is transported in the format as shown in FIGS. 1 1 A through 1 1 C, in 
which FIG. 1 1 A shows a unscrambled format. FIG. 1 1 B shows a scrambled format with respect to a bitstream, and FIG. 
1 1 C shows a format in which the bitstream is selectively scrambled. 
35 In the described embodiment, if the GA bitstream is scrambled, it is assumed that a protection of any kind will be 
applicable. 

Therefore, if scrambled stream data SKsfBSJ+E^KS) of the format shown in FIG. 11B or 11C is input to copy 
protection processor 4, a splitter shown in FIG. 10 splits the stream data into bitstreams S K s( B S)+lDX and keystreams 
E G (KS). Then, a recording mode is performed to encrypt again the split keystreams E°(KS) to then be transported to 
40 smart card 3. 

Here, as shown in FIG. 1 1 C, if the bitstreams are partially scrambled, the illegal view and copy protection function 
is adoptable only to the scrambled portion, thereby performing a partial protection function. 

First, when non-scrambled bitstreams are transported as shown in FIG. 11 A, even if the bitstreams modulated 
/demodulated and decrypted in demodulator & error corrector 1 are input to copy protection processor 4, the data is not 
4s transported to smart card 3. Either. ATV decoder 2 to which the bitstreams of demodulator & error corrector 1 are input 
does not transport the data to smart card 3 but decrypts the bitstream. 

Therefore, there is no restriction in view and copy. 

Here, the signal input from a tuner to demodulator & error corrector 1 and the video and audio signals output from 
ATV decoder 2 are analog signals. The signal output from tuner is a VSB-modulated signal from the GA-bitstream. 
so Among input/output signals, bitstreams and keystreams are digital signals for DVCR. 

At this time, if the recording is performed, the bitstreams are recorded onto DVCR and the recorded bitstreams are 
played back from a general DVCR. ^ . 

In other words, even if non-scrambled MPEG bitstreams are input to copy protection processor 4 and passes through 
splitter as shown in FIG. 10. there is no data transported to smart card 3 due to no key information, thereby allowing a 
55 free view and copy. 

Also, when the recording or copy protection functions are executed in the present invention, the split bitstreams and 
keystreams are transported to different lines from each other. The information on the copy protection method is trans- 
ported with an additional copy information field within the PES header. 
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At this time even if the scrambled bitstreams having no encrypted key are transported to an illegaluser of the publ.c 
channels the descrambling is not executed properly in the state where the key informat,on ,s removed. 
Tso the sp.it key is again encrypted to be transported. Thus, if there is no decryption algorithm, brtstreams cannot 

bB Ter^eln the described embodiment, an arbitrary field is used in the MPEG transport pr^oco. for the illega. view 

now be described with reference to FIGS ■ 1 « " ^ processor during recording or playback 

o, m cow .wording a th. k« intern**- ' £nw W ««no th. dw into bWrean» 

40 copy" or not (S1 10). « * nenerai recording tape, if there is no key information, and the 

m.tap.«d«™n*.s*«'«»n*notap.^^^ 

by the encryption algorithm E ak( • ) w^re^to ^ key™^ copy protects 

during the playback of the ^^^^^T^^sc^^)) b * encryptinfl 

processor 4 transports to smart card 3 ^X^o^% Lrmaton Ak if the back-up copy funct.cn ,s 
E Q (KS) by the encryption algorithm E ak( ) witn respeci wj » 
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At this time, if the keystream E G (KS) is input instead of the index code IDX, smart card 3 having determined the 
broadcasting view of PPV function decrypts the keystream E G (KS) by decryption algorithm 0 G ( * ) with respect to the 
bitstream GA (S1 1 6) and inputs the key information KS to ATV decoder 2 (Si 1 7). 

Accordingly, ATV decoder 2 reads the key information KS of smart card 3. determines a descrambling method and 
descrambles the bitstream S K s(BS) to output analog video and audio signals, thereby allowing a viewer to watch the 
broadcasting program. 

If it is determined" that the index code IDX is input in Si 15. smart card 3 decrypts the keystream Esc^tE^KS)] 
input from copy protection processor 4 by decryption algorithm 0 SC AK ( • ) with respect to the key information Ak (S1 18) 
and then determines whether the operation is a playback operation or a recording operation (S1 19). 

At this time, if it is determined that the operation is the playback operation in S1 19. smart card 3 decrypts the 
keystream E G (KS) by decryption algorithm D G ( • ) with respect to the bitstream GA (S1 1 6) and inputs the key information 
KS to ATV decoder 2 (S1 17). 

Accordingly. ATV decoder 2 reads the key information KS of smart card 3, determines a descrambling method and 
descrambles the bitstream S KS (BS) split in copy protection processor 4 by the determined descrambling method to 
output analog video and audio signals, thereby allowing a viewer to watch the recorded program of the tape. 

If it is determined that the operation is the recording operation in S 11 9, smart card 3 determines whether the function 
is the back-up copy function or not (S1 20). If the function is the back-up copy function, the keystream E G (KS) by decryp- 
tion algorithm D sc Ak ( * ) with respect to the key information Ak (S1 21 ). and then the decrypted keystream D^JE^KS)] 
by decryption algorithm D sc Ak ( • ) with respect to the key information Al (S122). 

At this time, the keystream D sc Ak {D sc A ,[E Q (KS)]} decrypted in smart card 3 is transported to recording side (S123) 
and is input to copy protection processor 8 through smart card 7 (S124) to then be encrypted by encryption algorithm 

ESCa|( ' ) - «r « 

Accordingly, smart card 7 inserts the encrypted keystream D^/^tE^KS)] into a position designated by the index 
code IDX and mixes the same with the bitstream S K s(BS) output from copy protection processor 4 of playback side to 
then be recorded onto the tape in VCR 9. 

If it is determined that the operation is the recording operation in S1 19. and it is determined in S120 that the PPP 
function is adopted, instead of the back-up copy function ), smart card 3 decrypts the keystream E Q (KS) by decryption 
algorithm D SC A) ( • ) with respect to the key information Al (S122) and transports the decrypted key information 
D SC A ,[E G (KS)] to recording side (S1 23). 

At this time, copy protection processor 8 of recording side, having received the keystream D SC AI [E Q (KS)] through 
smart card 7 encrypts the received keystream 0 S c AI [E Q (KS)l by the encryption algorithm E 80 ^ " ) and inserts the 
encrypted keystream [E G (KS)] into a position designated by the index code IDX. thereby mixing with the bitstream 
Sks(BS) output from copy protection processor 4 of playback side. Therefore, the bitstream S K s(BS)+E G (KS) output 
from copy protection processor 8 is recorded onto the tape by VCR 9. 

As described above, in the preferred embodiment, all smart cards have common algorithm and common key with 
respect to encryption algorithm E Q ( * ) and decryption algorithm D G ( ) for the MPEG bitstream. 

Also, the encryption algorithm E SC A |( * ) and decryption algorithm O sc Ak ( * ) for a smart card are common for all 
smart card. However, key information is different for the respective smart cards. 

In other words, each smart card contains an authentication key corresponding to its own identification (ID) in itself. 

In performing such operation, the initialization including an authentication process for identify their counterpart 
between the copy protection processor and the smart card, and between the smart cards and a key exchange process 
is necessary. 

At this time, as the authentication process, there has been proposed various methods such as a method of using 
symmetrical key algorithm like a DES algorithm, a method of using a public key algorithm like an RSA, or a method of 
using Fiat-Shamir (FS) scheme. 

In the described embodiment the public key algorithm is used in the authentication process and the key exchange 
method are illustrated in FIG. 21 . Such methods are adopted on the basis that a public key (n, e) is shared by a key 
reception means 201 and a key transport means 202. 

At this time, key reception means 201 is a copy protection processor or a smart card 1 of recording side, and key 
transport means 202 is its own smart card k. 

The embodiment of the present invention operating as shown in the above flowchart will now be described with 
reference to FIGS. 12 through 18. 

In the embodiment as shown in FIG. 1 1 A, if non-scrambled bitstream BS is transported, the circuit operates as 
shown in FIG. 12. Therefore, the bitstream modulated /demodulated and RS-decoded in demodulator & error corrector 
1 is decrypted in ATV decoder 2. thereby outputting analog video and audio signals. 

At this time, during recording operation, the bitstream BS output from demodulator & error corrector 1 is recorded 
onto the tape in VCR 5 through copy protection processor 4. During playback operation, the bitstream BS played back 
from VCR 5 is input to ATV decoder 2 through copy protection processor 4 and is decrypted, thereby outputting analog 
video and audio signals. 
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In other words, since the data is not generated from copy protection processor 4 to smart card 3. the view and copy 
are not affected. 

As shown in FIGS. 1 1 B and 1 1 C. if scrambled bitstream is input, the CA function is adopted to perform the operations 
shown in FIGS. 13 through 18. 

5 First, in case of performing the PPV function, the circuit operates as shown in FIG. 13. That is to say, if scrambled 

bitstream S K $(BS) and encrypted keystream E G (KS) are transported, demodulator & error corrector 1 demodulates the 
modulated input signal and then corrects the errors generated during transport through RS-decoding. 

At this time. ATV decoder 2 splits the keystream E G (KS) from the output S«s(BS)+E G (KS) of demodulator & error 
corrector 1 and outputs the same to smart card 3. Then, smart card 3 decrypts the encrypted keystream E G (KS) and 
w outputs again the keystream KS to ATV decoder 2. 

Accordingly. ATV decoder 2 reads the key information KS of smart card 3, determines a descrambling method and 
descrambles the bitstream S K s(BS) to output analog video and audio signals. 

As described above, smart card 3 shown in FIG. 9 allows processor 1 1 to decrypt the encrypted keystream E G (KS) 
and to output the decrypted keystream KS to ATV decoder 2 by decryption algorithm E G ( * ). 
is In the case of recording scrambled bitstream for the first time, the circuit operates as shown in FIG. 1 4. in which the 
transported bitstream S K s(BS)+E G (KS) is error-corrected in demodulator & error corrector 1 through RS-decoding and 
then is input to VCR 5 through copy protection processor 4 to then be recorded onto the tape. 

In the case of playing back the bitstream recorded as described above, if the function is PPP function, the system 
operates as shown in FIG. 15. If the bitstream S K s(BS)+E G (KS) played back from VCR 5 is input to copy protection 
20 processor 4. copy protection processor 4 splits the played-back bitstream S K s(BS)+E Q (KS) into the bitstream S K s(BS) 
and keystream E Q (KS) and then again encrypts the split keystream E°(KS) by encryption algorithm E sc Ak ( ■ ) to then 
output the same to smart card 3. The split bitstream S K s(BS) is output to ATV decoder 2 with the extracted portion of 
the keystream E G (KS) inserted with an index code IDX. 

At this time, smart card 3 having received the index code IDX through ATV decoder 2, decrypts the encrypted 
25 keystream E sc Ak [E G (KS)] of copy protection processor 2 by decryption algorithm D^a^ • ) for smart card and outputs 
the key stream (descrambling information) KS to ATV decoder 2 (S1 17). 

Accordingly. ATV decoder 2 reads the key stream KS of smart card 3. determines a descrambling method and 
decrypts the bitstream S K s(BS) input through copy protection processor 4, thereby outputting analog video and audio 
signals. 

30 Also, in the case of recording the data recorded as shown in FIG. 14 onto a different VCR, the PPC function is 
performed as shown in FIG. 16. If the bitstream S K s(BS)+E G (KS) played back from VCR 5 is input to copy protection 
processor 4, copy protection processor 4 spirts the bitstream S K s(BS)+E°(KS) into the bitstream S KS (BS) and keystream 
E°(KS) and then again encrypts the split keystream E G (KS) by encryption algorithm E 5 ^ * ) to then output the same 
to smart card 3. The split bitstream S K s(BS) is output to copy protection processor 8 of recording side with the extracted 

35 portion of the keystream E G (KS) inserted with the index code IDX. 

At this time, smart card 3 of playback side decrypts the keystream E^akIE^KS)] encrypted in copy protection 
processor 4 by decryption algorithm D^Ait " ) with respect to the key information Al stored in RAM 1 5 and then outputs 
the decrypted keystream D SC A ,[E G (KS)] to smart card 7 of recording side. 

Accordingly if smart qard 7 of recording side receives the keystream 0 SC A ,[E Q (KS)] of smart card 3 of playback 

40 side and outputs the same to copy protection processor 8. copy protection processor 8 encrypts the keystream 
D SC A |[E G (KS)] and restores the same into the original encrypted keystream E Q (KS). which is mixed with the bitstream 
G KS (8S) output from copy protection processor 4 of playback side according to the index code IDX to then be output to 
VCR 9. thereby recording the same onto another tape. 

The data of the tape recorded in the above-described operations adopts the PPP function and is played back as 

45 shown in FIG. 15.- 

Also, in the case of recording the data recorded as shown in FIG. 14 onto another VCR. the back-up copy function 
is performed as shown in FIG. 1 7. 

In other words, if the bitstream S K s(BS)+E Q (KS) played back from VCR 5 is input to copy protection processor 4, 
copy protection processor 4 splits the bitstream S K s(BS)+E G (KS) into the bitstream S KS (BS) and keystream E (KS) 
so and then again encrypts the split keystream E G (KS) by encryption algorithm E 550 ^ • ) to then output the same to smart 
card 3. The split bitstream S KS (BS) is output to copy protection processor 8 of recording side with the extracted portion 
of the keystream E Q (KS) inserted with the index code IDX. ^ _^ 

At this time, smart card 3 of playback side decrypts twice the keystream E^Akt^KS)] encrypted in copy protection 
processor 4 by decryption algorithm 0 s0 M ( ■ ) with respect to its own key information Ak stored in ROM 14 and then 
55 decrypts again by decryption algorithm 0 X M { * ) with respect to the key information Al stored in RAM 15 and then 
outputs the decrypted keystream D^AiP^Akt^KS)]} to smart card 7 of recording side. 

Accordingly, if the keystream D^ID^aJE^KS)]} of smart card 3 of playback side is output to copy protection 
processor 8 of recording side through smart card 7 of recording side, copy protection processor 8 encrypts the keystream 
D sc A1 {D sc A k[H G (KS)]} with respect to the key information Al and restores the same into the original encrypted keystream 
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D sc Ak [E G (KS)]. The restored D sc Ak (E G (KS)] is mixed with the bitstream G KS (BS) output from copy protection processor 
4 of playback side according to the index code IDX to then be output to VCR 9, thereby recording the same onto another 
tape. 

Here, the charge is counted in the improved smart card 3 or 7. 

The data recorded by performing/the back-up copy function can be played back only from the VCR recording the 
original tape. In the case of a normal playback, the operation is executed as shown in FIQ. 18 A. 

In other words, ilthe bitstream S K s(BS)+D sc A k[E Q (KS)] played back from VCR 5 is input to copy protection processor 
4, copy protection processor 4 splits the bitstream Sks^SJ+D^a^E^KS)] into the bitstream S K s(BS) and keystream 
D sc Ak [E G (KS)] and then again encrypts twice the split keystream D^AklE^KS)] by encryption algorithm E^^f ■ ) to 
then output the same to smart card 3. The split bitstream S K s(BS) is output to ATV decoder 2 with the extracted portion 
of the keystream D sc Ak [E G (KS)] inserted with the index code IDX. 

At this time, smart card 3 having received the index code IDX through ATV decoder 2 decrypts twice the keystream 
E SC Ak[E G (KS)] encrypted in copy protection processor 2 by decryption algorithm D sc Ak ( • ) for smart card and then 
outputs the key stream (descrambiing information) KS to ATV decoder 2. 

Accordingly, ATV decoder 2 reads the key stream KS of smart card 3, determines a descrambiing method and 
decrypts the bitstream S KS (BS) input through copy protection processor 4. thereby outputting analog video and audio 
signals. 

Also, in the case of an abnormal playback to another VCR not to the original recorded VCR, the operation is executed 
as shown in FIG. 18B. thereby disabling the playback of the tape. 

In other words, if the copied tape is played back from VCR to which the tape copy has been performed, copy pro- 
tection processor 8 splits the played-back data S KS (BS)+O sc Ak [E Q (KS)] to separate the bitstream S KS (BS)+tDX. 

At this time, the split bitstream D sc Ak [E Q (KS)] is encrypted with respect to its own key information Al and is again 
encrypted with respect to the key information Al to become E 30 ArfE^AilD^AklE^KS)])} to then be transported to smart 
card 7. 

At this time, smart card 7 cannot decrypt the keystream E^AiiE^AitD^AklE^KS)])}. so that the key information 
KS may not be transported to ATV decoder 6. 

Accordingly, smart card 7 cannot descrambles the bitstream S KS (BS) so that the copied tape cannot be played back. 

As described above, since the authentication and key exchange process are automatically performed during power- 
on or connection between DVCRs, the illegal view and copy protection function for illegal smart card can be automatically 
performed. Also, since the illegal view and copy protection is partially performed, the scrambling process is performed 
with respect to a protection-desired portion of a program, thereby performing the illegal view and copy protection auto- 
matically and levying the charge in a desirable manner. 

Also, in the described embodiment, since the split bitstream and keystream are transported to different paths, the 
protection data amount can be reduced, thereby efficiently performing the illegal view and copy protection. In imple- 
menting the illegal view protection and illegal copy protection for a smart card, the PPV. PPR PPC and back-up copy 
functions are differentiated, thereby levying the charges differentially for the respective functions. 

According to the described embodiment, the copy protection for digital signals, which is adoptable for DSM appli- 
cations can be implemented, which allows a program copyright protection for a DSM such as a DVCR. Therefore, the 
reliability for illegal view and copy protection is increased. 

Finally, in order to facilitate the understanding of the present invention, terms used in the specification will be defined 
as follows: 

1 ) BS: non-scrambled GA bitstream; 

2) KS=[Ko. K 1t K 2 ,... ^....KJ: keystream (Here, n is total number of keys used for scrambling.); 

3) BSa[BSo. BSi. BS 2t ... BSj^.-BSJ: bitstream (Here. BS* is one segment of BS and is a scrambling unit.); 

4) Sks(BSMS K o(BSo). S K i(BSi). S^BSJ.... S Ki (BS i )....SKn(BS„)]: scrambled GA bitstream; 

5) E( • )&D( * ): algorithms used for encryption and decryption of keys in GA; 

E Q (KSHE Q (K 0 ). E^K,). E G (K 2 ).... E Q (K j),...E G (K n )J and 
D G [E Q (KS)HD Q [E G (K 0 U D G [E Q (K 1 )]. D G [E G (K 2 )],... 
D G [E Q (K ()],... D G [E G (K n )U=KS; 



6) IDXsfO. 1, 2. .. n]: index stream; 

7) Ak: authentication key for smart card (k); and 
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8) E SC A ( • )&D SC A ( * ): encryption and decryption algorithms for smart card used the smart card authentication key 
(A) as the key. 

Claims 

5 

1 . An illegal view and copy protection method in a digital video system comprising: 

a determination step for determining received data of having been scrambled; 

a reproduction step, if the received data was determined to be scrambled data in the determination step, 
splitting the scrambled data into a bitstream and a keystream for decrypting the split keystream for reading in key 
w information, and descrambting the split bitstream according to the read in key information for displaying the bitstream 
on a display; 

a recording step for, if the received data was determined to be scrambled data in the determination step, 
recording the scrambled data on a recording medium either as scrambled data of a bitstream and a keystream 
according to a recording or copying mode, or after splitting the scrambled data into a bitstream and a keystream, 
is encrypting the split keystream, and mixing the encrypted keystream with the bitstream; and, 

a transporting step, if the received data was determined to be scrambled data in the determination step, 
splitting the scrambled data into a bitstream and a keystream for transporting the split keystream either after decrypt- 
ing the split keystream with respect to key information from recording side according to a P PC mode or a back-up 
copy mode, or after decrypting the split keystream two times with respect to key information of its own and key 
20 information from recording side; 

thereby the reproduction step, the recording step and the transporting step can be performed simultaneously 
or selectively. 

2. An illegal view and copy protection method in a digital video system as claimed in claim 1 . wherein, if the received 
25 data was determined to be unscrambled data in the determination step, said illegal view and copy protection method 

is not applied to the unscrambled data. 

3. An illegal view and copy protection method in a digital video system as claimed in claim 1 . wherein the reproduction 
step includes the step of decrypting said split keystream with a decryption algorithm, for reading in key information. 

30 - 

4. An illegal view and copy protection method in a digital video system as claimed in claim 1 . wherein a copying oper- 
ation in the recording step includes. 

a first step for encrypting the key stream with respect to its own key information, 
a second step for determining the encrypted keystream of being a back-up copy mode or a PPC mode. 
35 a third step for. if the mode was determined to be the PPC mode in the first step, encrypting the keystream 

transported after being decrypted with respect to the key information from a recording side, and then inserting the 
same into a position corresponding to an index code to record the same together with the bitstream. and 

a fourth step for, if the mode is determined to be the back-up copy mode in the second step, encrypting the 
keystream transported after being decrypted with respect to its own key information and the key information from a 
40 recording side with respect to the key information from a recording side, decrypting the same with respect to its own 
key information, and then inserting the same into a position corresponding to an index code, to record the same 
together with the bitstream. 

5. An illegal view and copy protection method in a digital video system as claimed in claim 4, 
45 wherein said PPC mode operation the third step includes. 

a first transportation step for transporting the scrambled data after splitting the bitstream and the keystream 
and inserting said index code into the split portion of said keystream. 

a second transportation step for transporting the keystream split in thef irst transportation step after encrypting 
the keystream with respect to its own key information and decrypting the same with respect to the key information 
so from a recording side. 

a recording step for recording the keystream transported in the second transportation step on a recording 
medium after encrypting the keystream with respect to the key information from a recording side in correspondence 
with the index code and mixing the same with the bitstream transported in the first transportation step. 

55 6. An illegal view and copy protection method in a digital video system as claimed in claim 5, wherein the reproduction 
operation after finish of the recording step includes. 

a splitting step for splitting the reproduced bitstream into a bitstream and a keystream and inserting an index 
code into the split portion of the keystream. 

an encrypting step for encrypting the keystream split in the splitting step with respect to its own key information. 
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a reading in step for reading in key information by decrypting the keystream encrypted in the encrypting step, 
with respect to its own key information, and 

a decrypting step for descrambling the bitstream split according to the key information read in in the reading 
in step. 

7. An illegal view and copy protection method in a digital video system as claimed in claim 4, wherein said back-up 
copy mode operation in the fourth step includes. 

a first transportation step for transporting the scrambled data after splitting the scrambled data into a bitstream 
and a keystream and inserting an index code into the split portion of the keystream, 

a second transportation step for transporting the keystream split in the first transportation step after encrypting 
the keystream with respect to its own key information and decrypting the encrypted keystream with respect to the 
key information from a recording side and its own key information, 

a recording step for recording the keystream transported in the second transportation step on a recording 
medium after encrypting the keystream with respect to the key information from a recording side in correspondence 
with the index code and mixing the same with the bitstream transported in the first transportation step. 

8. An illegal view and copy protection method in a digital video system as claimed in claim 7, 
wherein the reproduction operation after finish of the recording step includes, 

a splitting step for splitting the reproduced bitstream into a bitstream and a keystream and inserting an index 
code into the split portion of the keystream, 

an encrypting step for encrypting the keystream split in the splitting step with respect to its own key information, 

a reading in step for reading in key information by decrypting the keystream encrypted for two times in the 
encrypting step, with respect to its own key information and the MPEG bitstream, and 

a decrypting step for descrambling the bitstream split according to the key information read in in the reading 
in step. 

9. An illegal view and copy protection method in a digital video system comprising: 

a reproduction step, on reception of scrambled data, splitting the scrambled data into a bitstream and a 
keystream for decrypting the split keystream for reading in key information, and descrambling the split bitstream 
according to the read in key information for displaying the bitstream on a display: and. 

a recording step for, on reception of scrambled data, recording the scrambled data on a recording medium 
as scrambled data of a bitstream and a keystream; 

thereby the reproduction step and the recording step can be performed simultaneously or selectively. 

1 0. An illegal view and copy protection method in a digital video system as claimed in claim 9, wherein the reproduction 
step includes the steps of decrypting said split keystream with a decryption algorithm for reading in key information 
and determining a descrambling method with the read in key information. 

1 1 . An illegal view and copy protection method in a digital video system as claimed in claim 9. 
wherein the reproduction operation after finish of the recording step includes, 

a splitting step for splitting the reproduced bitstream into a bitstream and a keystream and inserting an index 
code into the split portion of the keystream, 

an encrypting step for encrypting the keystream split in the splitting step according to an encrypting algorithm 
with respect to its own key information, 

a reading in step for reading in key information by decrypting the keystream encrypted for two times in the 
encrypting step, with respect to its own key information, and 

a decrypting step for descrambling the bitstream split according to the key information read in in the reading 
in step for displaying on a display. 

12. An illegal view and copy protection method in a digital video system on reception of a keystream encrypted with 
respect to its own key information at copying, comprising: 

a determining step for determining the mode of the keystream being a back-up copy mode or a PPC mode; 

a first transportation step for, if the mode was determined to be a PPC mode in the determining step, decrypt- 
ing the keystream with respect to key information from a recording side for transporting the keystream; 

a first recording step for encrypting the keystream transported in the first transportation step with respect to 
the key information from the recording side and inserting the encrypted keystream into a position corresponding to 
an index code, for recording the keystream together with a bitstream on a recording medium; 

a second transportation step for, if the mode was determined to be a back-up copy mode in the determining 
step, decrypting the keystream for two times with respect to its own key information and the key information from 
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the recording side for transporting the keystream; and 

a second recording step for encrypting the keystream transported in the second transportation step with 
respect to the key information from the recording side and inserting the encrypted keystream into the position cor- 
responding to the index code, for recording the keystream together with the bitstream on a recording medium. 

5 

13. An illegal view and copy protection method in a digital video system as claimed in claim 12. 

wherein the jirst transportation step includes the steps for decrypting the keystream, encrypted with respect to its 
own key information, with respect to its own key information and decrypting the keystream again with respect to the 
key information from the recording side, for transporting the keystream. 

w 

14. An illegal view and copy protection method in a digital video system as claimed in claim 12. 

wherein the second transportation step includes the step for decrypting the bitstream. decrypted with respect to its 
own key information, for two times with respect to its own key information and decrypting the keystream again with 
respect to the key information from the recording side for transporting the keystream. 

15 

1 5. An illegal view and copy protection method in a digital video system, comprising: 

a PPC mode reproduction step for, having determined the recording medium being a PPC* recording medium 
on detection of a keystream at reproduction from a recording medium, encrypting the keystream with respect to its 
own key information and decrypting the keystream with respect to its own key information for reading in the key 

20 information, for descrambling the bitstream using both the read in key information and an index code; and, 

a back-up copy' mode reproduction step for, having determined the recording medium being a back-up copy' 
recording medium on detection of a keystream decrypted with respect to its own key information at reproduction 
from a recording medium, encrypting the keystream for two times with respect to its own key information and the 
key information from a recording side and decrypting the keystream with respect to its own key information for 

25 reading in the key information, for descrambling the bitstream using both the read in key information and an index 
code. 



16. An illegal view and copy protection device in a digital video system, comprising: 

demodulating & error correcting means for demodulating a broadcasting signal and RS-decoding said signal : 
30 copy protection processing means for transporting the output of said demodulating & error correcting means 

to a digital recording/reproduction device, splitting the scrambled recording signal reproduced from said digital 
recording/reproduction device into a bitstream and a keystream. and encrypting the split keystream; 

decoding means for descrambling the bitstream from said demodulating & error correcting means or the copy 
protection processing means according to descrambling information; and, 
35 a smart card for decrypting the encrypted keystream of said copy protection processing means for applying 

to said decoding means as descrambling information. 

1 7. An illegal view and copy protection device in a digital video system as claimed in claim 16. 

wherein said illegal view protection function is performed such that said decoding means connected to said demod- 
40 ulating & error correcting means is connected to said smart card to decode the keystream of said decoding means 
and the descrambling information is output to said decoding means. 

18. An illegal view and copy protection device in a digital video system as claimed in claim 16. 

wherein first recording is performed by connected said copy protection processing means connected to said demod- 
45 ulating & error correcting means to said digital recording/reproduction device. 

1 9. An illegal view and copy protection device in a digital video system as claimed in claim 16. 

wherein the illegal reproduction protection is performed such that a keystream line of said copy protection processing 
means connected to said digital recording /reproduction device is connected to said smart card, a bitstream line is 
so connected to said decoding means, and said copy protection processing means and said decoding means are 
connected to each other, so that said smart card decrypts the keystream of said copy protection processing means 
into its own key information corresponding to the index code of said decoding means to then output the same to 
said decoding means. 

55 20. An illegal view and copy protection device in a digital video system as claimed in daim 19. 

wherein said protection processing means encrypts twice the keystream split from reproduced data of said digital 
recording/reproduction during reproduction from a recording medium in a PPC mode with respect to its own key 
information and transports the same to said smart card. 
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21. An illegal view and copy protection device in a digital video system as claimed in claims 19, 

wherein said protection processing means encrypts the keystream split from played-backdata of said digital record- 
ing/reproduction device for more than two times during reproduction from a recording medium in back-up copy mode 
with respect to its own key information and transports the same to said smart card. 



22. An illegal view and copy protection device in a digital video system as claimed in one of claims of 16. 18 or 19, 
wherein said copy protection processing means includes 

a RAM for storing intrinsic key information of said smart card. 

an algorithm storage memory for storing an encryption algorithm, and 

a processor for executing an encryption program of said algorithm storage memory with the key information 



23. An illegal view and copy protection device in a digital video system as claimed in one of claims of 16. 1 7 or 19, 
wherein said smart card includes 



20 24. An illegal view and copy protection device in a digital video system comprising: 

first copy protection processing means for splitting reproduction data from a first digital recording /reproduction 
device into a bitstream and a keystream and encrypting the split keystream; 

first and second smart cards for decrypting encrypted keystream from said first copy protection processing 
means with respect to its own key information and the key information from a recording side; and. 
25 second copy protection processing means for encrypting the keystream from the first smart card transported 

through the second smart card with respect to its own key information and transporting the encrypted keystream 
together with the split bitstream to a second digital recording/reproduction device, for recording on a recording 
medium. 

30 25. An illegal view and copy protection device in a digital video system as claimed in claim 24, 

wherein said first copy protection processing means encrypts the keystream with respect to its own key information 
and transports the same to said first smart card. 

26. An illegal view and copy protection device in a digital video system as claimed in claim 24. 

35 wherein said smart card decrypts the keystream of said first copy protection processing means with respect to its 
own key information and the key information of recording side and then transports the same to said second smart 
card. 

27. An illegal view and copy protection device in a digital video system as claimed in claim 24, 

40 wherein said second copy protection processing means encrypts the keystream transported from said second smart 
card with respect to its own key information and mixes the same with the bitstream from said first copy protection 
processing means. 

28. An illegal view and copy protection device in a digital video system as claimed in claim 24, 

45 wherein said first smart card decrypts the keystream from said first copy protection processing means twice with 
respect to its own key information during a back-up copy mode and decrypts the same with respect to the key 
information from a recording side. 

29. An illegal view and copy protection device in a digital video system as claimed in claim 24. 

so wherein said second copy protection processing means encrypts the keystream transported from said second smart 
card with respect to its own key information and mixes the encrypted keystream with the bitstream. 

30. An illegal view and copy protection device in a digital video system as claimed in claim 24. 
wherein each of said first and second copy protection processing means includes 

55 a RAM for storing intrinsic key information of said smart card. 

an algorithm storage memory for storing an encryption algorithm, and 

a processor for executing an encryption program of said algorithm storage memory with the key information 
of said RAM. 



5 



of said RAM. 
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a first algorithm storage memory for storing a decryption algorithm program for a bitstream. 
a second algorithm storage memory for storing its own decryption algorithm program, 
a ROM for storing its own key information, and 
a RAM for temporarily storing key information of another smart card. 



14 



BNSOOC1D:<£P 0714204A2> 



EP 0 714 204 A2 



31. An illegal view and copy protection device in a digital video system as claimed in claim 24, 
wherein each of said first and second smart cards includes 

a first algorithm storage memory for storing a decryption algorithm program for a bitstream. 
a second algorithm storage memory for storing its own decryption algorithm program, 
a ROM for storing its own key information, and 
a RAM for temporarily storing key information of another smart card. 



10 



15 



20 



25 



30 



35 



40 



45 



50 



55 



BNSOOCIO:<£P 0714204A2> 



EP 0 714 204 A2 



F.I G.I 
pnor art 



U(o) 



U(s) 



0£S 



OES 



DES 



1-112 



■r 



Eu(o)Eu(s)(ck) 



— Eck(PK) 



OES 



7> 



WK 



114 
i- 



4w 



101 



scrarnbiinq, excutinq party | 



SVo 



OEC:dota encryption standard 



F. I G.2 
pnor art 



u(.) 



U(s) 



102 

-4- 



informat'on 
processor 



A(o) A(«) 



D*(o)rDufs)(CK)l 
0*(s)[0»(.)[Eck(PK)l 



E*(p)[E*(s)(WK)] 



103 

-4- 



smart cd(j ) 



TT 

A(o) A(s) 



16 



EP 0 714 204 A2 



F. I G.3 
pnor art 



r— transport header 





PES header 

fr 


xed length 




| audio 


video 


audio 


1 audio 


video 

^ 


| video 


| audio 


video 



bytes* vouuGE t«HyfiL£. 





pajtoad 



/ a in 



Syncbyte 
(0^7) 



13 



P1D 



^xadaptation-field_lenqth "Sftcfypt^ jcrambling key 



r 



length 
fiekj(l) 



bytes 



transport,scrambllng_control 
Ofcpot ^ramWed 

00: em key transpoct_private_datQ_flog 
11: odd key set to 1 

01: 



17 



8NSOOCIO:<EP 0714204A2> 



EP 0 714 204 A2 



/' 



F.I G.4 

prior art 



transport header 
PES header 



transport stream; I audio 

✓ 



audi 



video 



pqyiood 



fix ed leng th 



audio 



i 



audio 



video 



| video | 



I audio 



video 



/ 2* Sfe 1 fife. Iff b& 2Ms- H bits 8 b& 



iWprfr j-ir - 


PES pact* 

fiwsth- 


"to 




PES taadK 


fES heodec 
fMdr 


rr-P€S pgdafc- 
dotd tiucte 



1111 



sc 



PR 



OA 



CR 



OC 



PO ESCR 



RATE 



0:Not exist 
1:3 bits 



OO.Not exist a 
10:40 bits / 
11:80 bib fpTS 
OTS 




variable length 




OSU trick 'additional copy'ES extension] extension 
MOPE field! fitto" | flags jdoto field 



shuffling 
bytes 



18 



8NSOOC1D:<EP 07M204A2> 



EP 0 714 204 A2 



transport header 
transport stream 



r 



F. I G.5 
pfloc art 

transport., private. data=K j»»t 





















transport. scramblin$_control ] 
=*od<fkey ] 


j l .» ! 
[transport, scramblmg_control | 

=* even* key | 


[transport 


_scrambling_control 
=* odd" key 


descrambling with 


descrambiing with ' 
K* 


descrambiing with 


! ~ smart card Ka*i 



time necessary for decryption 



F I G.6 
[trior art 



front 
hmr 



demodulator & 
error correction 



-1- 

104 



ATV decoder 

105 



transport 
demultiplexer 




cornpres96it ' 
vtdto 



memory 106 
f ( 107 



video decode* 



compressed 
oudo 



audio decodep-4- 

ii 



eontro</<tata ,[^i cro CO ntroHec]^i09 



snort cord 



to 



to 



no 



smart ccrd 



smart card 
(private algorithms) 



103 



19 

8NSOOC1D: <£P 071 4204 A2> 



EP 0 714 204 A2 



F I G.7 



1 set 



from 
tuner 



bitstrearii 



keystreojft 



demodulator 
dt error 
corrector 

— i — 



■ 



1 



AW decoder 



transport 
demultiplexer 



copy protection 
processor 



record^ 



3-4 



play back- 



conventional 
OVCR 



memory 
1 — 



compressed 
video 



J video decoder 



compressed 
audio 



audio decoder 



control/data 



T 



micro controller 



; KS 



itQ 



display 



!to 



bitstrwm 



— 3 



smart card 

(private algorithms 
and circuits) 



keystream 



20 



8NSOOCIO: <EP 07142O4A2> 



EP 0 714 204 A2 



F I G.8 



bitstrecm 



r 



t 



bitstream 

(To ATV decoder) 



processor 



to conventional 
OVCR ) 



:M6 



RAM 

(for key)A»+-17 



to 

smart cord 



encryption 
algorithm for 
smart cord ' ^18 

£«(-) 



from 

smart card 



from conventional 
OVCR 



F L G.§ 



from 

copy protection 
Processor 



to 

copy protection. 
Processor 



to 

ATV decoder 



decryption 
algorithm for 

2^ 

12 



ROM 
(for key)Ak 



from 

ATV decoder 



Processor 



1t 



14 



decryption 
atqorithr 



algorithm for 
smart card 

Pg» 4-13 



keystream 



keystream 



RAM 
(for key)AI 



15 



21 



BNSOOCID: <EP 0714204A2> 




EP 0 714 204 A2 



S*(3s)+E c (cs) 



se,:::er 



F I G.10 

Sc(8S)+IOX 



(E^ks)] 



sr.artcard k — 



t 



<3 

(to AW decoder) 
(to other OVCR) 



F I G.11a 



Nonrscrambled GA 
>itsti 



bitstream 
— BS 



BS. 



BS, 



BS, 



8Si 



f J G.11b 

. transporLprivate.data. 



scambled GA 
bitstream 



|E c (k,) Su(BS,)|E c (k.) S M (BSt)fc'M Si(BSi)--£*(k.)Sii (BSi) 
— Sc(BS)+E e (ks) 



F! G.11c 



l«d|E c (k.) 


S*(BS#) 


BSi 


BS, 


E c (kO 


S« (BSi] 





F I G.11d 



S*(BS)+!DX 



S» (BS.) 



S M (BS,) 



S« (BS,) 



S* (BSi 



f (ks) |E c (k0)| 



F I G.11e 



window signal 



E e (ki| k'ca] 




E e (ki) 




i F 1 G.11f 

1 1 1 
1 1 t 


i 

< 


1 

: 





22 



BNS0OCI0:<£P 0714204A2> 



EP 0 714 204 A2 



F I G.12 



8S demodulator k 
error-corrector 



ss 



BS 



copy protection " "" * * No doto* ; 
Processor 



8S 



ATV decoder 



— 2 



"No data"! "No data" 



1 



3S 



conventional _e 
DVCR 



— 3 



smart 
card 



F I G.13 



S«s(as)+£ 6 (KS) 



demodulator k 
error-corrector 



t 



S c (3S)& KS -descrec mblinq 



Sb(BS)»£ c (KS) _ | 



[ ".""4-4 
i copy protection i 

! Processor ! 



1 conventional 4_ ^ 



A1V decoder 



--2 



OVCR 



KS 



E 5 (KS) 



-3 



smart 
card 



23 



BNS0OCI0:<EP 0/1 4204 A2> 



EP 0 714 204 A2 



F I G.14 



Sg(9S)+6*(ltt) ! demodulator * 
i error-corrector 



Sc(3S)+E«(k3) 



copy protection 
Processor 



-~4 



conventional 
OVCR 



'-5 



ATV decoder 



i 




F I G.15 



demodulator & ! 
error-corrector i 



Si c (BS)& KS -descreo mblinq 



So(BS)+10X 



copy protection 
Processor 



t 



E5fE«(KS)l 




-3 



S«(8S)+6 c (la) 



smart 
card 



conventional 
OVCR 



— 5 



24 



EP 0 714 204 A2 



2 

4- 



F I G.16 



ATV 
decoder 



s«s(as)+iox 



4- 



copy protection 
Processor 



ScJBS^b) 



conventional ^ c 
OVCR ^ 



smart 
card 

k 



tr. 



ATV decoder 



i 



4- 



coqy protection 
Processor 



Stt(8S)+6 c (ks) 



conventional ^ Q 
OVCR 



smart 
card 



F I G.17 



ATV 
decoder 



Sc(BS)+IOX 



■4- 



copy protection 
Processor 



Se(BS)+€ c (to) 



I converttiond „e 
OVCR 



f-3 

I 



smart ! 
card 

k ! 



ATV decoder 



u 



copy protection 
Processor 



!s«(as)+o*[E*Mi 
J 



conventional _ Q 
OVCR " 



smart 
card 



V. • - — J 



T 



OiF[3jf[E c (k3)|l 



25 



BNS0OCI0:<£P 07M204A2> 



EP 0 714 204 A2 



F I G.18a 



Sg(BS)+tDX 




S«(8S)+0l[E«(to)] 



conventional _ e 
OVCR 



F I G.18b 



s«(BS)+um 




+ 



copy protection 
Processor 



i 



conventional 
OVCR ^ y 



26 



BNSOOCIO: <£P 0714204A2> 



EP 0 714 204 A2 



F I G.19a 



S101 

input:" 3S* or ^~ 
'So(BS)+E 6 (KS)"or 

'S«$(BS)+IOJf 



from copy protection I 
processonE S [S 6 (^)f 




Encryption alqorithoi 

«(•» 



Authentication 
key Ak(from ROM) 



S106 

4- 



To OVCR(recording) 



27 



EP0 714 204 A2 



F I G.19b 



Authentication 
key Ak 



S107 

• ' 

input" BS" or ' 
•S c (8S)+E 5 (KS)"or 

•Sc(BS)+02[E 6 (ks)]or 

"Sc(BS)+Oj[E c (ks)r 



splitter 



S108 



So 
or 



^|S)+IDX 



decoder 
or other set 



E c (ks) or 
D* E e (ks 




or 



Encryption algorithm 
(ES(-» 



t S1 12 
1-4 



I [Encryption algorithm 



. S1 13 

■1 — i — 



to smart card 
:ESP(ks)l 



28 

8NSOOCI0:<EP 0714204A2> 



EP 0 714 204 A2 



from copy protection 
processor:£s[£ c (ks)] 



Authentication 
key Ak(from ROM) 



target smart card 
Al (from RAM) 



from other OVCR 



F l G.20 



SI 1 4 

-4 — 



from A?/ cecoder: 
E 5 (KS) or IOX 




decrypUon algorithm 

(0S(-)) 



T 

f S119 
Noi S120 




decryption algorrthm 

(DS(-)) 
1 



Yes 



i 



decryption algorithm 

(DSN) . 
1 Y 



S122 



J 



S123 



to smart card: 



1_ 



SI 24 
-4- 



to copy protection 
processor 





S116 
f I 


decryption algorithm 

(o 6 b 




S117 


to ATV decoder. 

KS 



29 



BNSOOC1D:<£P 0714204A2> 



EP 0 714 204 A2 



F I G.21 



Y=Z«(mod n) 



feftmRQftf 




30 



8NS0OCID: <EP 071 4204A2> 



(19) 



J 



02) 



(88) Oate of publication A3: 

11.06.1997 Bulletin 1997/24 

(43) Oate of publication A2: 

29.05.1996 Bulletin 1996/22 

(21 ) Application number: 95308493.6 

(22) Oate of filing: 27.1 1 .1 995 



Europaisches Patent a mt 
European Patent Office 
Office europeen des brevets (11) EP 0 71 4 204 A3 

EUROPEAN PATENT APPLICATION 

(51) Int. CI 6 : H04N 5/913 



(84) Designated Contracting States: 
DE FR GB 

(30) Priority: 26.11.1994 KR 9431364 

(71) Applicant: LG ELECTRONICS INC 
Seoul (KR) 



(72) Inventor: Park, Tae Joon 
Seoul (KR) 

(74) Representative: Cross, Rupert Edward Blount et 
al 

BOULT WADE TENNANT 
27 Furnival Street 
London EC4A 1 PQ (GB) 



CO 



CM 



(54) Illegal view and copy protection method In digital video system and controlling method 
thereof 



(57) Illegal view and copy protection method in a 
digital video system for preventing an illegal user from 
viewing the digital video system and copying therefrom, 
by setting a descrambting method which decrypts split 
keystreams adopting a smart card, including a determi- 
nation step for determining received data of having 
been scrambled; a reproduction step, if the received 
data was determined to be scrambled data in the deter- 
mination step, splitting the scrambled data into a bit- 
stream and a keystream for decrypting the split 
keystream for reading in key information, and descram- 
bting the split bitstream according to the read in key 
information for displaying the brtstream on a display: a 
recording step for. if the received data was determined 
to be scrambled data in the determination step, record- 
ing the scrambled data on a recording medium either as 
scrambled data of a bitstream and a keystream accord- 
ing to a recording or copying mode, or after splitting the 
scrambled data into a bitstream and a keystream. 
encrypting the split keystream. and mixing the 
encrypted keystream with the bitstream; and a trans- 
porting step, if the received data was determined to be 
scrambled data in the determination step, splitting the 
scrambled data into a bitstream and a keystream for 
transporting the split keystream either after decrypting 
the split keystream with respect to key information from 
recording side according to a PPC mode or a back-up 
copy mode, or after decrypting the split keystream two 
times with respect to key information of its own and key 
information from recording side: thereby the reproduc- 
tion step, the recording step and the transporting step 
can be performed simultaneously or selectively. 



F I G.7 





roal 




LU 



8NSOOC10:<EP 07142O4A3> 



EP 0 714 204 A3 



European Patent 
Office 



EUROPEAN SEARCH REPORT 



Apou'catioa Number 

EP 95 30 8493 



DOCUMENTS CONSIDERED TO BE RELEVANT 



Category 



Citation of document with indication, where appropriate, 
of relevant passages 



Relevant 
to daim 



CLASSIFICATION OF IXE 
APPLICATION flaiXXn) 



EP 0 519 320 A (MATSUSHITA ELECTRIC 
INDUSTRIAL CO., LTD.) 
* column 5, line 56 - column 7, line 27; 
examples 2-4 * 

EP 0 588 535 A (PIONEER ELECTRONIC 
CORPORATION) 



* column 2, line 50 - column 11, line 29; 
figures 1,5,6 * 

EP 0 267 039 A (SATELLITE TECHNOLOGY 
SERVICES, INC. ) 

* column 3, line 20 - column 4, line 38; 
figure 1 * 

US 5 455 860 A (HI RASHMA) 

* column 5, line 48 - column 6, line 11; 
figure 1 * 



The 



i draw* up> for all 



1,9,12. 
15,16,24) 



1.9,12. 
15,16, 
19,23, 
24,31 



1,2,9, 
12.15, 
16.24 



1,9,12, 
15,16,24 



H04N5/913 



TECHNICAL FIELDS 
SEABCHED (laLCL*) 



H04N 



s 

3 

3 

2 



THE HAGUE 



Oatt • 



9 April 1997 



Verleye, J 



CATEGORY OF CITED DOCUMENTS 

X : particularly relevant if taken alone 

Y : parties tarty relevant if essoinee with another 

document of the same category 
A : technoJogical background 
O : non-written disclosure 
P : intermediate document 



T : theory or principle underrytan the avi ati on 
E : earlier patent iocs nest, hut pooh thee on, or 

after the ftliog date 
D : document cited in the app l i cati o n 
L : document cited for other reasons 



& : member of the sa 
document 



r patent family, im ie saua dinf. 



SNSOOCID:<EP 0714204A3> 



This Page is Inserted by IFW Indexing and Scanning 
Operations and is not part of the Official Record 

BEST AVAILABLE IMAGES 

Defective images within this document are accurate representations of the original 
documents submitted by the applicant. 

Defects in the images include but are not limited to the items checked: 

□ BLACK BORDERS 

□ IMAGE CUT OFF AT TOP, BOTTOM OR SIDES 

□ FADED TEXT OR DRAWING 

13 BLURRED OR ILLEGIBLE TEXT OR DRAWING 

□ SKEWED/SLANTED IMAGES 

□ COLOR OR BLACK AND WHITE PHOTOGRAPHS 

□ GRAY SCALE DOCUMENTS 

□ LINES OR MARKS ON ORIGINAL DOCUMENT 

□ REFERENCE(S) OR EXHIBIT(S) SUBMITTED ARE POOR QUALITY 

□ OTHER: _J_ 

IMAGES ARE BEST AVAILABLE COPY. 
As rescanning these documents will not correct the image 
problems checked, please do not report these problems to 
the IFW Image Problem Mailbox. 



THIS PAGE BLANK (uspto) 



